An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
netiq access manager 4.3 |
||
netiq access manager 4.2 |